Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Audit & Certification

Approved Scanning Vendor

Also known as: ASV, ASV scan solution provider
Simply put

An Approved Scanning Vendor (ASV) is an organization that the PCI Security Standards Council has authorized to perform external vulnerability scans of an organization's internet-facing systems as part of PCI DSS compliance. Before a vendor can appear on the Council's official list, its scanning solution must be tested and approved by the PCI SSC. Organizations that need such scans can locate qualified vendors through the official list maintained by the PCI Security Standards Council.

Formal definition

An Approved Scanning Vendor (ASV) is an organization qualified by the PCI Security Standards Council (PCI SSC) to deploy an ASV scan solution—security services and tools used to conduct external vulnerability scanning against systems in scope for the Payment Card Industry Data Security Standard (PCI DSS). Qualification is contingent on the vendor's scan solution being tested and approved by PCI SSC prior to inclusion on the Council's List of Approved Scanning Vendors, and on staff and security personnel completing the associated ASV training and qualification program. ASV status pertains specifically to external scanning obligations under PCI DSS and is distinct from other PCI SSC roles such as Qualified Security Assessors (QSAs); it reflects a contractual/scheme-based qualification within the PCI DSS framework rather than a statutory legal designation. The canonical designation is 'Approved Scanning Vendor'; the variant 'Authorized Scanning Vendor' appears informally but is not the official PCI SSC term. ASV program requirements, versions, and the vendor list change over time, so readers should verify current status and requirements against the official PCI SSC source.

Why it matters

External vulnerability scanning is a recurring obligation within the PCI DSS framework for organizations with internet-facing systems in scope for the standard. Because PCI DSS is a scheme-based, contractual set of requirements rather than a statutory law, the party performing these scans generally cannot be just any security firm—the scanning solution must be one that the PCI Security Standards Council has tested and approved. The ASV designation exists to give organizations a reliable way to identify vendors whose scanning solutions have passed this vetting, reducing the risk that a scan is later rejected as non-conforming when compliance is assessed or reported to acquirers and payment brands.

For compliance and information security teams, using an approved vendor matters because the results of ASV scanning typically feed into an organization's demonstration of PCI DSS compliance. Selecting a vendor not on the Council's official list may leave an organization unable to satisfy the external scanning requirement, forcing rework. It is worth emphasizing that ASV status reflects qualification within the PCI DSS scheme; it is not a legal license or a government designation, and it does not by itself establish overall PCI DSS compliance—it addresses only the external scanning portion.

Because ASV program requirements, versions, and the list of approved vendors change over time, teams should verify a vendor's current status against the official PCI SSC source rather than relying on prior engagements or third-party recommendations. Notably, payment service providers such as Adyen have stated that they cannot recommend a specific ASV, since the scanning engagement must be performed independently by an approved vendor.

Who it's relevant to

Compliance officers overseeing PCI DSS programs
Those responsible for maintaining PCI DSS compliance need to understand that external vulnerability scans must generally be performed by a vendor drawn from the Council's official List of Approved Scanning Vendors, and that ASV scanning addresses only the external scanning obligation rather than compliance as a whole. They should verify a vendor's current listing against the official PCI SSC source before engaging.
Information security teams managing internet-facing systems
Security personnel responsible for internet-facing infrastructure in scope for PCI DSS interact directly with ASV scanning of those systems. Understanding what an ASV scan solution covers helps these teams scope their environment and coordinate remediation of findings, though the application of results to a specific environment requires professional judgment.
Vendors seeking ASV qualification
Organizations that wish to offer external scanning services under the PCI DSS scheme must have their scan solution tested and approved by PCI SSC and must have their staff and security personnel complete the associated ASV training and qualification program before appearing on the Council's list. Program requirements and versions change over time and should be confirmed against the current official PCI SSC materials.
Merchants and service providers selecting a scanning vendor
Entities that must arrange external scans, including those working with payment service providers, should note that some providers decline to recommend a specific ASV because the engagement must be performed independently by an approved vendor. Such organizations should consult the official PCI SSC list to identify qualified vendors.

Inside ASV

PCI SSC Qualification
An ASV is an organization qualified by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scanning services. The qualification is granted through a program administered by the Council and is subject to the Council's testing and validation processes.
External Vulnerability Scanning
The core service an ASV provides: scanning of internet-facing systems and network components to identify vulnerabilities. This addresses the external scanning obligations that arise under the PCI DSS (Payment Card Industry Data Security Standard), which is a contractual standard imposed by the payment card brands and acquirers rather than a statutory regulation.
Scope of ASV Scans
ASV scanning generally covers externally accessible (internet-facing) infrastructure within the cardholder data environment. It is distinct from internal vulnerability scanning and from penetration testing, which serve different purposes and are typically performed separately.
Scan Report and Attestation
The output typically includes a scan report and an attestation of scan compliance intended to demonstrate that in-scope external systems meet the applicable scanning requirements. Report content and formatting are defined by PCI SSC program documentation; practitioners should verify the current format against the latest Council materials.
Contractual, Not Statutory, Basis
The requirement to use an ASV derives from PCI DSS obligations, which apply to entities that store, process, or transmit payment card data through their agreements with card brands and acquirers. This is a standard enforced contractually, not a law with jurisdiction-based statutory force, though its practical reach can be broad.

Common questions

Answers to the questions practitioners most commonly ask about ASV.

Is an ASV the same as an "Authorized Scanning Vendor"?
No. The canonical designation defined by the PCI Security Standards Council is "Approved Scanning Vendor." The variant "Authorized Scanning Vendor" is sometimes used informally by vendors or blogs, but it is not the official PCI SSC term. When referring to the program in contracts, reports, or compliance documentation, use "Approved Scanning Vendor" and verify current terminology against PCI SSC's published materials.
Does passing an ASV scan mean an organization is fully PCI DSS compliant?
No. An ASV scan addresses only the external vulnerability scanning requirements within PCI DSS; it is one component of a broader set of obligations and does not by itself establish overall PCI DSS compliance. Passing scan results should not be equated with certification against the full standard. Organizations generally must satisfy numerous other requirements, and the applicable validation path depends on merchant or service provider level and how the environment is assessed. This distinction between a single scan and full compliance is important to keep separate.
Who is required to engage an ASV?
PCI DSS is a contractual standard imposed through payment card brand and acquirer agreements rather than a law of general application, so obligations are driven by those agreements. In most cases, organizations that have external-facing systems within scope of the cardholder data environment are expected to obtain external vulnerability scans from an ASV, but the specifics depend on the organization's assessed level and its environment. Whether the requirement applies, and how often, should be confirmed with the relevant acquirer or payment brand and against the current PCI DSS text.
How does an ASV scan differ from an internal vulnerability scan?
An ASV performs external scans from outside the network, and only a vendor listed by PCI SSC can produce results that satisfy the ASV scanning requirement. Internal vulnerability scans are generally performed from within the environment and, in most cases, may be conducted by qualified internal staff or third parties without ASV listing. The two serve related but distinct purposes and are not interchangeable; readers should verify the applicable scan frequency and scope against the current standard.
What does an ASV scan result typically indicate, and what are its limitations?
An ASV scan result generally reflects the presence or absence of externally detectable vulnerabilities at the time of the scan against defined criteria, producing a pass or fail determination. Its scope is limited to external scanning; it does not assess internal controls, policies, physical security, or other PCI DSS requirements, and it represents a point-in-time view rather than continuous assurance. Interpretation of results and remediation of findings require professional judgment, and the applicable pass criteria should be verified against current PCI SSC guidance.
How can an organization confirm that a scanning vendor is a valid ASV?
PCI SSC maintains a listing of vendors that hold current ASV status. Because a vendor's listing status can change over time, organizations should generally verify a prospective vendor against the current published list rather than relying on prior engagements or vendor self-description. This entry does not cover the vendor's internal qualification process; confirm current status and program details directly with PCI SSC.

Common misconceptions

"Authorized Scanning Vendor" is a valid alternative name for an ASV.
The canonical PCI SSC designation is "Approved Scanning Vendor." Variants such as "Authorized Scanning Vendor" appear informally in some vendor materials and blogs but are not the official term and should be avoided in formal or contractual contexts.
An ASV scan is equivalent to a penetration test and satisfies all testing obligations.
ASV scanning is automated external vulnerability scanning and is distinct from penetration testing, which typically involves manual and deeper exploitation-oriented testing. PCI DSS generally treats these as separate requirements, and an ASV scan does not by itself fulfill penetration testing obligations.
PCI DSS and the ASV requirement are government regulations with legal force everywhere.
PCI DSS is a standard enforced through contracts with the payment card brands and acquiring banks, not a statute enacted by a legislature. Obligations arise from those contractual relationships rather than from jurisdiction-specific law, although some sectors or agreements may reference it.

Best practices

Confirm that a prospective scanning vendor holds current ASV qualification through the PCI SSC before engaging them, since qualification status and program versions change over time.
Use the exact designation "Approved Scanning Vendor" in contracts, policies, and attestations, and avoid informal variants that could create ambiguity.
Treat ASV external scanning as one component of a broader testing program, and maintain separate arrangements for internal scanning and penetration testing where required.
Verify that the scope of external, internet-facing systems provided to the ASV is accurate and complete, since incomplete scope can undermine the validity of the resulting attestation.
Retain ASV scan reports and attestations of scan compliance in accordance with your program's requirements, and confirm current report formats against the latest PCI SSC documentation.
Verify all specific ASV program requirements, scanning frequencies, and report formats against the current authoritative PCI SSC materials rather than relying on prior versions, and seek professional judgment for how obligations apply to your specific environment.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps